INTL India - Remote Splunk Engineer

Insight Global
Boston, United States of America
8 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
English
Compensation
$ 31K

Job location

Boston, United States of America

Tech stack

API
Cloud Computing
Computer Security
Python
Mitre Att&ck
REST
Splunk

Requirements

Strong SPL knowledge and ability to write complex searches, optimize them, and explain why they perform the way they do

-Hands-on Splunk data onboarding experience - forwarders, HEC, API inputs, props/transforms, field extractions

-CIM normalization - understanding of the data models, you know how to validate compliance, and you know what breaks when a source is not normalized

-Splunk Enterprise Security - correlation searches, notable events, data model acceleration

-Index management - retention policies, tiered storage, capacity planning

-Experience with Splunk ES in a security operations context, not just as a log aggregation tool -Risk-Based Alerting (RBA) implementation and tuning

-ESCU - deploying, customizing, and maintaining Splunk's detection content library

-Python - scripted inputs, custom Splunk commands, REST API integrations

-Familiarity with MITRE ATT&CK and how it maps to Splunk data sources and detection content

-Splunk Cloud administration

-Experience with CrowdStrike, Microsoft Defender, or Entra ID log sources specifically

-Splunk certifications - Splunk Core Certified Power User or above

Benefits & conditions

$10/hr to $15/hr

Exact compensation may vary based on several factors, including skills, experience, and education.

Benefit packages for this role will start on the 31st day of employment and include medical, dental, and vision insurance, as well as HSA, FSA, and DCFSA account options, and 401K retirement account access with employer matching. Employees in this role are also entitled to paid sick leave and/or other paid time off as provided by applicable law.

About the company

Insight Global is seeking a remote Splunk Engineer to join a global consulting firm. This person will be the person who shapes how this organization collects, normalizes, and operationalizes security telemetry across the organization. You would work directly with the Continuous Monitoring & Detection function to ensure every detection rule has a validated, high-fidelity data source behind it. You would be working on the ingestion pipeline, the health of our log sources, and the quality of the data the organizations CSIRT depends on to detect and investigate threats. If you are someone who likes to proactively identify data quality issues before they become detection gaps, push back when someone wants to onboard a source that cannot meet the minimum field requirements, and treat the ingestion pipeline as a security control, not an IT service, this is the position for you!

Apply for this position